The chrome team is clearly in the wrong here, and it will take some time for them to realize that they screwed up and that they need to fix it.
The chrome team is clearly in the wrong here, and it will take some time for them to realize that they screwed up and that they need to fix it.
That's just how you make unpopular changes these days.
Maybe the EU will do something about it, but this will take years.
This isn't "clear" to me. There are certainly complaints about this change within HN, but there are also people here saying that they appreciate the change, or that they're ambivalent.
But the more important part of things is that HN has what, maybe 10000 active users? Chrome has over a billion. Even if every HN commenter was vehemently against this change, that's less than 1% of 1% of Chrome's user base. If this change makes the browser better (using whatever metric you want, I'd argue the correct one here is privacy), even marginally, for the average user, at the cost of a few people believing that the browser is behaving badly, that seems like an overall good change, doesn't it?
And that seems to be what the Chrome team is arguing, that while some "abnormal" users might see this as an attack on privacy, it isn't, and it's a privacy increase for the uninformed user.
I think I've seen exactly one potentially compelling argument, which is that it may now be easier to accidentally enable syncing when you don't want to, since its a single click instead of entering a password. That might be true, although I'm not 100% certain, since I've logged into the wrong chrome window before, and that would have enabled syncing in a previous world.
First off, since it applies to people logged out of Chrome and it forces them to log in it increases, not decreases, the chances of someone accidentally leaving their account available to others on the machine. Since the sync button no longer requires a password this means someone can log in at a library to check their email, walk away, and someone else can step up, hit the sync button, and steal all of their information.
They've just made people less secure, not more.
But lets take your argument and assume it's right. You could apply the same logic to every website on the internet- Amazon, people's bank accounts, phone companies, etc. Google is therefore abusing their status as the browser developer to give themselves special functionality that other websites can't give. This should open them up to a variety of antitrust actions (particularly in the EU).
At the end of the day this could have been done by letting people opt-in to the login. Add a button on the google login sites that say "log into browser as well" and let the people who want it click it.
I'm still against this Chrome change for the same reasons, but I would hope other libraries do the same thing as we did. From my experience library tech people are usually really privacy focused.
In my experience, 9 out of 10 libraries, copy shops and internet cafés don't do this [properly].
As a public entity we had a mandate to protect user information and make sure it wasn't stored by us or accessible by others. This applied across the organisation from what books someone checked out to what websites they visited.
Maybe this was just more of a thing in Canada or even Alberta but the concept was definitely agreed upon with other libraries and people in the system I was in contact with. I have read other articles and such from American libraries about protecting information so I assumed it was more widespread.
Before, if you were logged into both Chrome and Gmail, you could log out of one and forget to log out of the other. Now, logging out of a Google site also logs you out of Chrome.
> Since the sync button no longer requires a password this means someone can log in at a library to check their email, walk away, and someone else can step up, hit the sync button, and steal all of their information.
If you have access to someone's email account, you can already steal quite a lot of information.
As written this feature enables special privileges unavailable to other website developers via a direct integration with the browser. Imagine if some other company automatically added a feature directly to your browser without your consent. You would be rightfully angry if there was a yahoo/facebook/microsoft widget that you didn't approve being added to your toolbar. What's stopping the chrome team from adding more features to blur the line between the browser and google services?
There are boundaries between websites, browsers, and users that should not be violated. This is nothing more than google putting their thumb on the scale to unfairly influence user behavior in their interest.
More importantly, doing so without users clearly knowing and consenting to it is a clear violation of GDPR. This is an absolute, not a relative standard. Which means that it doesn't matter how it compares to what things were like before.
This for Google could be up to a $2 billion fine. 2% of worldwide annual revenue - annual revenue is around $100 billion. It would only take 13 fines per year of that size to reduce Google to not being profitable.
So you shouldn't think about it as a question of opinions about UI design. Instead think about it as a question of liability. Do you as an employee want the people working on Chrome to be subjecting your employer to this kind of legal risk?
If this change did that, I might be inclined to agree with you. But as far as I know, it doesn't. You still have to explicitly opt in to syncing. Which is a no-op compared to the old behavior.
> The personal information that Chrome stores won't be sent to Google unless you choose to store that data in your Google Account by signing in to Chrome.
If what you are saying is true- and will remain true for the future- why didn't they change that language to say something like-
> The personal information that Chrome stores won't be sent to Google unless you choose to store that data in your Google Account by signing in to Chrome and enabling syncing.
[1] https://www.google.com/chrome/privacy/#signed-in-chrome-mode
Seriously though, searched for "signed in" (like, ctrl-f). There's an epic ton of things that they are allowed to do for signed in accounts versus normal browsing even with sync disabled. These are all directly quoted from the privacy policy and do not require syncing to be enabled-
* If you are signed in to a Google site or signed in to Chrome and Google is your default search engine, searches you perform using the address bar in Chrome are stored in your Google account.
* Payments. If you are signed in to the Chrome browser and you have credit cards stored in your Google Payments Account, then Chrome will offer you the option of filling those cards into web forms. In addition, if you enter a new credit card into a web form, Chrome will offer to save your credit card and related billing information to your Google Payments account.
* Language. In order to customize your browsing experience based on languages that you prefer to read, Chrome will keep a count of the most popular languages of the sites you visited. This language preference will be sent to Google to customize your experience in Chrome. If you are signed in to Chrome, this language profile will be associated with your Google Account and, if you include Chrome history in your Google Web & App Activity, may be used to personalize your experience in other Google products. View Activity Controls.
Note the "or". If you're signed into Google and you do a Google search, that's stored in your account by default. The only reason signing into Chrome is relevant is that that also signs you into Google.
> * Payments. If you are signed in to the Chrome browser and you have credit cards stored in your Google Payments Account, then Chrome will offer you the option of filling those cards into web forms. In addition, if you enter a new credit card into a web form, Chrome will offer to save your credit card and related billing information to your Google Payments account.
This doesn't suggest any data being sent to Google unless you accept the offer to save a card to your Google Payments account.
> * Language. In order to customize your browsing experience based on languages that you prefer to read, Chrome will keep a count of the most popular languages of the sites you visited. This language preference will be sent to Google to customize your experience in Chrome. If you are signed in to Chrome, this language profile will be associated with your Google Account and, if you include Chrome history in your Google Web & App Activity, may be used to personalize your experience in other Google products. View Activity Controls.
Okay, this is one actual example of signing in causing more data to be sent to Google than would happen otherwise. It seems pretty benign, though.
> > * If you are signed in to Chrome and Google is your default search engine, searches you perform using the address bar in Chrome are stored in your Google account.
If you are signed into the browser but aren't signed into Google this states it will still save your search query.
Does this change your opinion?
>I think I've seen exactly one potentially compelling argument, which is that it may now be easier to accidentally enable syncing when you don't want to, since its a single click instead of entering a password.
Personally, though, (and I want to highlight that this is just my opinion as a person) I don't think it's a regression. But I can understand why others might disagree. From what I've read, the old behavior was that logging in enabled syncing by default. So accidentally logging in would immediately sync things.
I've certainly made the mistake of logging into the wrong account in the wrong chrome window, so I could absolutely see a user making the same mistake previously.
But even if you disagree, I think "you can synchronize by mistake, so they should add a confirmation dialogue" (which is a change I would support!) puts this firmly into the realm of imperfect UX and not an attack on privacy that should be totally rolled back.
And the aggravating (and potentially harmful) thing is that we can't even approach the discussion of "should we add a confirmation box", which would address the UX issue, if the accusation is that it's an attack on privacy. First we have to have this long tiring discussion where people throw around words like "Orwellian" and "GDPR" and we get to the reality that people are complaining about a whole host of not-really-harmful things, and that the one actually-maybe-harmful thing is a confirmation dialogue.
For a cautionary note, consider carefully how Microsoft got away with losing antitrust lawsuit after antitrust lawsuit and laughing about the consequences...until the EU decided to raise the stakes on them. And then read https://www.cnbc.com/2017/06/27/the-largest-fines-dished-out... to remind yourself how the EU thinks of Google.
Now I personally am opposed to the EU approach. (The upcoming copyright laws are particularly worrisome to me.) But at some point Google is going to need to leave the EU, or else to follow EU law. I don't believe that Google is willing to exit the EU. In which case you should really be worried about parts of Google that are putting the whole company at risk by violating EU law. No matter what you, personally, think of said EU laws.
Well what percentage of those billion users understands what's going on, versus the 10000 users here? Google's business model does depend on duping people who don't know any better, so maybe this isn't so surprising..
In any case, I don't think there'd be so much uproar if Google hadn't snuck the change in without telling anybody. There are release notes, why not use them? Why is that so hard to understand for a company that prides itself on hiring the best and brightest?
How does automatically signing me into Chrome improve my privacy?
I am sorry but "abnormal users" is just funny. Who is "normal" and cares about privacy?
Consider the case of two users, Alice and Bob. Alice has sync enabled, Bob does not.
Bob wants to check his email on Alice's computer, so he logs Alice off and logs into to his account. This syncs across all website he visits (due to shared auth cookies), but doesn't sync to the browser itself. Chrome is still logged into Alice's account, so Bob's browsing history is synced, but to Alice's history. This can have any number of unwanted consequences, from privacy consequences to Bob depending on whether or not you think Alice or Google are bad/compromised, to weirdnesses for Alice when she tries to check her history again.
Post this change, Bob logging in to Gmail on Alice's computer will log out of Alice on Chrome, and log in to Bob, meaning that Bob's history is no longer synced. So for Bob, this is a privacy increase (since now Google and Alice have less access to his browsing history) in that situation, and a usability improvement for Alice.
You could maybe get a similar effect by having account consistency be a thing that always logs the current user out and only also logs you in if you opt in, but that can also I think lead to weird situations for everyday users.
In other words, the point of signing in is to make sure no one else can accidentally (or intentionally) siphon away your browsing history.
Don't do that then.
There's a simple solution to this conundrum, but it involves google not hoovering up the browsing history of half the world by default. Unsurprisingly, the google team has decided not to implement that solution and instead has tied logins on a web page to logins in a browser ever more tightly, and this move is just another step on that road, until you can tell yourself that 99% of the world logs in to the browser, because it's just easier, so we'll make it opt out instead, and then by a series of small incremental steps, each of which seems reasonable, you're forcing users to log into google and send them your data to get any browsing done at all.
Logging in to the browser is the problem here, not the solution. You should log in to websites, not the browser, that separation is a good one and is there for very good reasons.
But I'll bite. In the scenario you just described, can't Alice still just look at her local history and get all of the same information? I just tested -- local history is accessible across accounts in Chrome 69.
So this change doesn't actually protect people who are sharing computers -- a private browsing session is what protects them. And this change doesn't make private browsing any easier.
Also in this scenario, if Bob isn't checking his email or something, he's very unlikely to go log Alice out of her account. So the extremely minor privacy boost that doesn't actually exist because all of Bob's history is still stored locally will still only happen if both Alice and Bob use Gmail.
Which makes it sound like this entire feature was the brainchild of some executive who genuinely can't comprehend someone borrowing a computer and not immediately signing into Gmail. A much better solution to the problem you're describing above would be to draw more attention to private browsing sessions in the UX, or to just have some kind of notification when the user signs out of Gmail.
Heck, you could have the same exact feature, except drop the auto-login part and only have the auto-logout. That would still be a useless feature because of the reasons above, but it would get rid of the vast majority of the privacy concerns the tech community is currently raising.
Auto-login is not necessary to fix the problem you're talking about.
Doesn't work. Between the cookie pop-ups, update notifications, and "you've got mail"s, people have learned to ignore pop-up notifications.
... of course, the real problem here started with "Bob checked his email on Alice's computer." There are so many ways it can go wrong, like Alice using a browser other than Chrome, Bob using an email service other than GMail, or Alice deliberately installing a keylogger on that computer...
To me that seems like a decrease in privacy.
Notably, synced data would have been visible in myaccount.google.com already, and if he had syncing disabled, I don't think there wouldn't be any data synced with his account to view.
In other words, assuming Alice was nefarious, yes this is still terrible, but I don't think it's just still terrible, not worse terrible.
Edit: I'm rate limited, but to clarify, yes syncing is an account wide setting, hence you need to be authenticated to a specific account to change it. The entire point of syncing is to sync data between browsers on different devices.
That makes no sense at all unless syncing is an account wide setting instead of a browser setting, and it's pretty clear that this is a browser setting. Bob could have syncing enabled on his primary computer, log into gmail on Alice's computer where it then logs him in to her browser but without syncing enabled, and then Alice can later on come in and enable syncing by hitting the blue button.
Frankly it sounds like what Google should have done is created a better security system rather than a better notification system. This solves nothing, creates more problems, and pisses people off at the same time.
How about this scenario:
Alice has Chrome synced to her Google account on her PC.
Bob uses Chrome on his PC but has no Google account and does not log in to Google services. He does uses bookmarks though.
Alice visits Bob and borrows his PC to check her gmail, which logs her in to Bobs Chrome. Then either Alice at that time or Bob at a later date accidentally triggers sync in Bobs Chrome.
TWO bad things happen at this point.
1) all Alice's synced data is downloaded onto Bob's PC. Including her bookmarks and passwords
2) all Bob's bookmarks are synced with Alice's account and Chrome on her PC will download them next time it's online.
I agree with you that this would upset Alice when she wants to check her personal browsing history. But isn't that the innate consequence of sharing your own computer with other persons? It is the same as Alice lending her MacBook to Bob without logging out herself first. Can't Alice simply log out her Chrome before giving to Bob?
Bob logging in to Gmail on Alice's computer will log out of Alice on Chrome, and log in to Bob
Why should Gmail (or any Google service) be so special? If Bob log in to his Outlook account, shouldn't the same treatment happen (which clearly indicate a persona switch)? It is clear that Google is using its monopoly power between Google services and Chrome to reinforce the bond between "average users" and itself. Imagine if Chrome dwindles at ~10% market share instead. Do you ever think the Chrome team would have done this feature?